skip to content

Under NIST SP 800-30 Rev. 1, what are the four steps of a risk assessment, and how does ISO 27005 structure the same work?

level: middleimportance: should knowfreq 40%

answer

  1. guide for conducting risk assessments
  2. prepare before you conduct
  3. six conduct tasks end in risk
  4. assessment is never one-time
  5. context, assess, treat, accept

basics

~20 s

NIST SP 800-30 Rev. 1 runs prepare, conduct, communicate results and maintain; conducting identifies threat sources, threat events, vulnerabilities, likelihood, impact and finally risk. ISO/IEC 27005 frames the same work as context, identification, analysis, evaluation, treatment and acceptance, with continual monitoring.

solid answer

~50 s

SP 800-30 Rev. 1 (September 2012) is NIST's guide to the *assess* component of the frame-assess-respond-monitor cycle from SP 800-39. Its four steps are: **Prepare** — purpose, scope, assumptions and constraints, information sources, and the risk model and analytic approach (Tasks 1-1 to 1-5); **Conduct** — threat sources, threat events, vulnerabilities and predisposing conditions, likelihood, impact, and risk as a combination of the two (Tasks 2-1 to 2-6); **Communicate** results to decision makers and share supporting information (Tasks 3-1, 3-2); **Maintain** — monitor risk factors and update the assessment (Tasks 4-1, 4-2). ISO/IEC 27005 is the ISO guidance behind ISO 27001's risk requirements: establish context, then risk assessment as identification, analysis and evaluation, then treatment and acceptance, wrapped in communication and consultation and monitoring and review. Both treat assessment as iterative, not a one-off report.

go deeper

for a junior

Recall the four SP 800-30 steps in order and that ISO 27005 is guidance supporting ISO 27001, not a certificate of its own.

for a middle

Explain what each step produces, including the Prepare choices of risk model, assessment approach and analysis approach, and map the steps onto ISO 27005's phases.

for a senior

Show how you run a repeatable assessment: fixing scales and tolerance up front, making uncertainty explicit in the results, and keeping the assessment maintained as systems change.

for a principal

Discuss choosing between NIST and ISO methods for an organization pursuing several frameworks, and how one assessment process can serve both without duplicating work.

## Where SP 800-30 sits **NIST SP 800-30 Rev. 1, *Guide for Conducting Risk Assessments*** (September 2012) is guidance, not a certification. It describes one component of the risk management process defined in **SP 800-39**, which has four components: **frame** (assumptions, constraints, risk tolerance, priorities), **assess**, **respond** and **monitor**. SP 800-30 covers the *assess* component only; choosing a risk response is a separate component, which the assessment informs. Assessments can be run at three tiers: Tier 1 (organization), Tier 2 (mission or business process) and Tier 3 (information system). For US federal systems it is the assessment guidance behind SP 800-53 control `RA-3` and the Risk Management Framework; for everyone else it is voluntary guidance that many programmes adopt. ## The four steps | Step | Tasks | What happens | |---|---|---| | **1. Prepare for the assessment** | 1-1 to 1-5 | Identify the purpose, the scope, the assumptions and constraints, the sources of threat, vulnerability and impact information, and the risk model and analytic approach | | **2. Conduct the assessment** | 2-1 to 2-6 | Identify threat sources, threat events, vulnerabilities and predisposing conditions; determine likelihood, adverse impact, and then risk | | **3. Communicate results** | 3-1, 3-2 | Communicate results to decision makers to support risk responses; share risk-related information with appropriate personnel | | **4. Maintain the assessment** | 4-1, 4-2 | Monitor the risk factors on an ongoing basis; update the assessment with what monitoring finds | Task 2-6 determines risk "as a combination of likelihood and impact" and asks the assessor to make uncertainty explicit, including assumptions and subjective judgements. ## Decisions made in Prepare Prepare is where most quality is won or lost. Two choices shape everything after: - **Assessment approach** — *quantitative*, *qualitative* or *semi-quantitative* (section 2.3.2). Qualitative scales support communication but compress results; quantitative results support cost-benefit analysis of alternative responses but lose rigour when subjective judgements are buried in them. - **Analysis approach** — *threat-oriented*, *asset/impact-oriented* or *vulnerability-oriented*: which of the risk factors the analysis starts from. The risk model, value scales and the organization's risk tolerance are fixed here so that different assessors produce comparable results. ## The ISO/IEC 27005 parallel **ISO/IEC 27005** (current edition 2022) is the ISO guidance for information security risk management and supports the risk assessment and treatment requirements of ISO/IEC 27001. It is not a certification; an organization is certified against ISO 27001 and may use any method that meets that standard's requirements. The standard is paywalled, so its structure is described here without clause numbers: 1. **Context establishment** — scope, criteria for risk acceptance and for performing assessments. 2. **Risk assessment**, split into identification, analysis and evaluation against the criteria. 3. **Risk treatment** — choosing options and producing a treatment plan. 4. **Risk acceptance** of the residual risk by the risk owners. 5. Around all of these, **communication and consultation** and **monitoring and review**. The 2022 edition describes both an **event-based** approach (start from scenarios) and an **asset-based** approach (start from assets, threats and vulnerabilities) to identification. ## Mapping the two | NIST SP 800-30 / 800-39 | ISO/IEC 27005 | |---|---| | Frame (in SP 800-39) and Prepare | Context establishment | | Conduct, Tasks 2-1 to 2-3 | Risk identification | | Conduct, Tasks 2-4 to 2-6 | Risk analysis and evaluation | | Respond (SP 800-39, outside SP 800-30) | Risk treatment and acceptance | | Communicate | Communication and consultation | | Maintain | Monitoring and review | The main difference in emphasis: SP 800-30 treats the assessment as a self-contained activity feeding a separate response component, and gives detailed tables for adversarial threat characteristics (capability, intent, targeting). ISO 27005 puts treatment and acceptance in the same process description. ## Common misreadings - Treating the report as the end; SP 800-30's fourth step exists because risk factors change. - Skipping Prepare and arguing about ratings later because nobody fixed the scales. - Assuming ISO 27001 requires ISO 27005 verbatim; it requires a defined, repeatable process that produces consistent, valid and comparable results.

  • Which SP 800-30 step do programmes most often neglect, and what does that cost?
    Maintain. Teams run a thorough assessment, issue the report and stop, so ratings drift away from reality as systems, threats and controls change. Tasks 4-1 and 4-2 call for monitoring the risk factors and updating the assessment, which is what lets a risk owner rely on a rating months later instead of commissioning a new assessment from scratch.
  • In SP 800-30, what is the difference between the assessment approach and the analysis approach?
    The assessment approach is the value scale: quantitative, qualitative or semi-quantitative. The analysis approach is the starting point for reasoning: threat-oriented, asset/impact-oriented or vulnerability-oriented. Both are chosen in Prepare (Task 1-5) together with the risk model, and they are independent: a threat-oriented analysis can be scored on a qualitative or a quantitative scale.

saying these in an interview costs you the question

  • A risk assessment is finished once the report is delivered.
  • SP 800-30 is a certification an organization can be audited against.
  • ISO 27001 certification requires following ISO 27005 exactly.
  • Choosing the risk response is one of the SP 800-30 assessment steps.
  • The risk model can be chosen after the ratings are in.